CyberMax
Home › Exploited CVEs › Roundcube

Roundcube Webmail known exploited vulnerabilities, ranked

CISA KEV catalog 2026.10.02 · FIRST EPSS scores from 2026-10-02

CISA lists 7 Roundcube Webmail CVEs as exploited in the wild. 2 were added in the last 12 months and 0 are known to be used in ransomware. The table ranks all of them by EPSS, FIRST's estimate of the chance a CVE is exploited in the next 30 days, so the first rows are the ones to patch first.

Patch these first

All 7 Roundcube Webmail CVEs in CISA KEV, by EPSS

#CVEFlawEPSSRansomwareAddedFederal due
1CVE-2025-49113RoundCube Webmail Deserialization of Untrusted Data98.9%–2026-02-202026-03-13
2CVE-2024-42009RoundCube Webmail Cross-Site Scripting82.9%–2025-06-092025-06-30
3CVE-2020-13965Webmail Cross-Site Scripting (XSS)76.6%–2024-06-262024-07-17
4CVE-2023-5631Webmail Persistent Cross-Site Scripting (XSS)75.9%–2023-10-262023-11-16
5CVE-2024-37383RoundCube Webmail Cross-Site Scripting (XSS)73.3%–2024-10-242024-11-14
6CVE-2023-43770Webmail Persistent Cross-Site Scripting (XSS)63.7%–2024-02-122024-03-04
7CVE-2025-68461RoundCube Webmail Cross-site Scripting26.8%–2026-02-202026-03-13
EPSS changes daily; a CVE with a low EPSS that is in KEV is still exploited somewhere. Federal due dates bind US federal civilian agencies; everyone else can use them as a priority hint. Sources: CISA KEV, FIRST EPSS.

More: all Roundcube KEV CVEs · free KEV badge for Roundcube · all vendors